Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-12530

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()_CVE-2026-12530

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 m...

AWS bedrock-agentcore 1.1.3 CVE
HIGH 7.1 CVE-2026-48759

TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)_CVE-2026-48759

TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme T...

baptisteArno typebot.io < 3.16.0 CVE
HIGH 7.5 CVE-2026-45617

LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex_CVE-2026-45617

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html fi...

harttle liquidjs < 10.26.0 CVE
HIGH 7.2 CVE-2026-53676

CVE-2026-53676_CVE-2026-53676

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can lo...

ThingsBoard ThingsBoard prior to v4.3.1.2 CVE
HIGH 7.5 CVE-2026-45357

LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)_CVE-2026-45357

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime...

harttle liquidjs < 10.26.0 CVE
HIGH 8.8 CVE-2026-55202

Tinyproxy – Stathost Detection Bypass via Host Header Manipulation_CVE-2026-55202

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated a...

tinyproxy tinyproxy CVE
HIGH 7.4 CVE-2026-55201

Evil-WinRM – Path Traversal in download_dir() Function_CVE-2026-55201

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or comp...

Hackplayers evil-winrm CVE
HIGH 8.2 CVE-2026-55199

libssh2 – Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler_CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in s...

libssh2 libssh2 CVE
HIGH 7.5 CVE-2026-10696

CVE-2026-10696_CVE-2026-10696

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community cat...

Devolutions UniGetUI CVE
HIGH 8.1 CVE-2026-50107

NGINX Gateway Fabric vulnerability_CVE-2026-50107

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX confi...

F5 NGINX Gateway Fabric 2.3.0 CVE